CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
975 | CVE-1999-0995 | Entry | Windows NT Local Security Authority (LSA) allows remote attackers to cause a denial of service via malformed arguments to the LsaLookupSids function which looks up the SID, aka "Malformed Security Identifier Request." | View | |||
554 | CVE-1999-0570 | Candidate | Windows NT is not using a password filter utility, e.g. PASSFILT.DLL. | Proposed (19990728) | ACCEPT(1) Northcutt | MODIFY(1) Frech | NOOP(2) Baker, Christey | REJECT(1) Wall | Northcutt> Here we are crossing into the best practices arena again. However since | passfilt does establish a measurable standard and since we aren"t the | ones defining the stanard, simply saying it should be employed I will | vote for this. | Frech> XF:nt-passfilt-not-inst(1308) | XF:nt-passfilt-not-found(1309) | Christey> Consider MSKB:Q161990 and MSKB:Q151082 | View |
199 | CVE-1999-0200 | Candidate | Windows NT FTP server (WFTP) with the guest account enabled without a password allows an attacker to log into the FTP server using any username and password. | Modified (19991130-01) | ACCEPT(1) Baker | MODIFY(2) Frech, Shostack | NOOP(2) Northcutt, Wall | REJECT(1) Christey | REVIEWING(1) Levy | Shostack> WFTP is not sufficient; is this wu-, ws-, war-, or another? | Frech> Other have mentioned this before, but it may be WU-FTP. | POSSIBLY XF:ftp-exec; does this have to do with the Site Exec allowing root | access without anon FTP or a regular account? | POSSIBLY XF:wu-ftpd-exec;same as above conditions, but instead from a | non-anon FTP account and gain root privs. | Christey> added MSKB reference | CHANGE> [Christey changed vote from REVOTE to REJECT] | Christey> The MSKB article may have confused things even more. There | were reports of problems in a Windows-based FTP server called | WFTP (http://www.wftpd.com/) that is not a Microsft FTP | server. It"s best to just kill this candidate where it | stands and start fresh. | View |
967 | CVE-1999-0987 | Entry | Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name. | View | |||
179 | CVE-1999-0179 | Entry | Windows NT crashes or locks up when a Samba client executes a "cd .." command on a file share. | View |
Page 175 of 20943, showing 5 records out of 104715 total, starting on record 871, ending on 875